A vulnerability classified as problematic was found in Azure kafka-sink-azure-kusto up to 5.2.2. Affected by this vulnerability is an unknown functionality of the component Connector Configuration Handler. The manipulation results in improper neutralization of special elements in data query logic. This vulnerability is known as CVE-2026-42316. It is possible to launch the attack remotely.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | kafka-sink-azure-kusto | < 5.2.3, < 5.2.2 |
Updated description with new details, changed affected versions to < 5.2.2, updated severity to HIGH, and noted that the vulnerability is actively exploited.
Initial creation